List workspace API keys
Full sessions only; org.settings.manage.
View as MarkdownAuthorization
bearer In: header
Path Parameters
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/workspaces/string/api-keys"{ "api_keys": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "kind": "string", "name": "string", "workspace_id": "string", "token_prefix": "string", "role": "string", "tools": [ "string" ], "last_used_at": "2019-08-24T14:15:22Z", "expires_at": "2019-08-24T14:15:22Z", "created_at": "2019-08-24T14:15:22Z", "secret": "string" } ]}Toggle a tool
Team workspaces only; org.tools.manage. Despite PUT, a single-tool upsert. Success returns the full GET shape.
Create a workspace API key
Full sessions only; team workspaces only; org.settings.manage. role honored (member or admin, never owner). 200 with show-once secret. `billing` is refused with `code: billing_key_unusable`. A key exists to call APIs and there is no API a billing principal can call: every product gates on the tool check, which refuses a role holding no product seat, and org.billing.manage is carried by the matrix but used by no route. The key would authenticate and 403 on everything else, so it is refused at creation rather than discovered in production.